CINXE.COM

Security | Linux Foundation

<!doctype html><html><head> <meta charset="utf-8"> <meta name="description" content="The Linux Foundation works to develop secure software in our foundations and projects, but mistakes can happen. Here's how to report a security vulnerability in something we do."> <title>Security | Linux Foundation</title> <meta name="viewport" content="width=device-width, initial-scale=1"> <meta property="og:description" content="The Linux Foundation works to develop secure software in our foundations and projects, but mistakes can happen. Here's how to report a security vulnerability in something we do."> <meta property="og:title" content="Security | Linux Foundation"> <meta name="twitter:description" content="The Linux Foundation works to develop secure software in our foundations and projects, but mistakes can happen. Here's how to report a security vulnerability in something we do."> <meta name="twitter:title" content="Security | Linux Foundation"> <style> a.cta_button{-moz-box-sizing:content-box !important;-webkit-box-sizing:content-box !important;box-sizing:content-box !important;vertical-align:middle}.hs-breadcrumb-menu{list-style-type:none;margin:0px 0px 0px 0px;padding:0px 0px 0px 0px}.hs-breadcrumb-menu-item{float:left;padding:10px 0px 10px 10px}.hs-breadcrumb-menu-divider:before{content:'›';padding-left:10px}.hs-featured-image-link{border:0}.hs-featured-image{float:right;margin:0 0 20px 20px;max-width:50%}@media (max-width: 568px){.hs-featured-image{float:none;margin:0;width:100%;max-width:100%}}.hs-screen-reader-text{clip:rect(1px, 1px, 1px, 1px);height:1px;overflow:hidden;position:absolute !important;width:1px} </style> <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.2/css/all.min.css"> <link rel="stylesheet" href="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/template_assets/77282239896/1669227111472/2022_-_BZ_Linux_Foundation_Theme/assets/vendor/magnific.min.css"> <link rel="stylesheet" href="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/template_assets/85121828485/1712254049681/2022_-_BZ_Linux_Foundation_Theme/assets/css/partials/mega-header.min.css"> <link rel="stylesheet" href="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/module_assets/77362524751/1712755318894/module_77362524751_Main_Mega_Footer.min.css"> <style> @font-face { font-family: "Roboto Slab"; font-weight: 400; font-style: normal; font-display: swap; src: url("/_hcms/googlefonts/Roboto_Slab/regular.woff2") format("woff2"), url("/_hcms/googlefonts/Roboto_Slab/regular.woff") format("woff"); } @font-face { font-family: "Roboto Slab"; font-weight: 300; font-style: normal; font-display: swap; src: url("/_hcms/googlefonts/Roboto_Slab/300.woff2") format("woff2"), url("/_hcms/googlefonts/Roboto_Slab/300.woff") format("woff"); } @font-face { font-family: "Open Sans"; font-weight: 400; font-style: normal; font-display: swap; src: url("/_hcms/googlefonts/Open_Sans/regular.woff2") format("woff2"), url("/_hcms/googlefonts/Open_Sans/regular.woff") format("woff"); } @font-face { font-family: "Open Sans"; font-weight: 700; font-style: normal; font-display: swap; src: url("/_hcms/googlefonts/Open_Sans/700.woff2") format("woff2"), url("/_hcms/googlefonts/Open_Sans/700.woff") format("woff"); } </style> <!-- Added by GoogleTagManager integration --> <script> var _hsp = window._hsp = window._hsp || []; window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} var useGoogleConsentModeV2 = true; var waitForUpdateMillis = 1000; var hsLoadGtm = function loadGtm() { if(window._hsGtmLoadOnce) { return; } if (useGoogleConsentModeV2) { gtag('set','developer_id.dZTQ1Zm',true); gtag('consent', 'default', { 'ad_storage': 'denied', 'analytics_storage': 'denied', 'ad_user_data': 'denied', 'ad_personalization': 'denied', 'wait_for_update': waitForUpdateMillis }); _hsp.push(['useGoogleConsentModeV2']) } (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-WWBXMJK'); window._hsGtmLoadOnce = true; }; _hsp.push(['addPrivacyConsentListener', function(consent){ if(consent.allowed || (consent.categories && consent.categories.analytics)){ hsLoadGtm(); } }]); </script> <!-- /Added by GoogleTagManager integration --> <link rel="canonical" href="https://www.linuxfoundation.org/security"> <script src="https://cmp.osano.com/16A0DbT9yDNIaQkvZ/af2b9f1f-3ac7-4a18-a99a-e487d04f08e6/osano.js?variant=two"></script> <script type="text/javascript" src="//d2c7xlmseob604.cloudfront.net/tracker.min.js" defer></script> <script> $(document).ready( function() { SmartlingContextTracker.init({ orgId: '-BHEtmsmrUGOM8sNYfeBSQ' }); }); </script> <!-- Google Tag Manager --> <script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-WWBXMJK');</script> <!-- End Google Tag Manager --> <meta property="og:url" content="https://www.linuxfoundation.org/security"> <meta name="twitter:card" content="summary"> <meta http-equiv="content-language" content="en"> <link href="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/template_assets/77283435922/1712081688750/2022_-_BZ_Linux_Foundation_Theme/assets/css/main.min.css" rel="stylesheet"> <meta name="generator" content="HubSpot"></head> <body class=" "> <!-- Added by GoogleTagManager integration --> <noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-WWBXMJK" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript> <!-- /Added by GoogleTagManager integration --> <div id="hs_cos_wrapper_language_switcher" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module widget-type-language_switcher" style="" data-hs-cos-general-type="widget" data-hs-cos-type="module"><span id="hs_cos_wrapper_language_switcher_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_language_switcher" style="" data-hs-cos-general-type="widget" data-hs-cos-type="language_switcher"></span></div> <div id="hs_cos_wrapper_module_16560108726164" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style="" data-hs-cos-general-type="widget" data-hs-cos-type="module"> <section id="mega-menu" class="section--module_16560108726164 section--mega-menu bg--black__slight page_header"> <div class="top__bar bg--secondary"> <div class="top__bar-wrapper section-wrapper flex-row jc--space-between"> <p class="top__bar--callout text-color--white"><span style="font-size: 16px;"><span style="color: #ffffff;">🎫 KubeCon + CloudNativeCon India · Dec 11-12 · Delhi </span><a href="https://events.linuxfoundation.org/kubecon-cloudnativecon-india/register/?utm_campaign=KubeCon%20India&amp;utm_source=LF&amp;utm_medium=Top-banner" rel="noopener" style="text-decoration: underline;">REGISTER TODAY</a></span></p> <div class="right-items flex-row align-items--center jc--end"> <div class="menu--language"> <svg class="icon--globe" width="13" height="12" viewbox="0 0 13 12" fill="none" xmlns="http://www.w3.org/2000/svg"> <path d="M6.33333 0.166748C3.11159 0.166748 0.5 2.77834 0.5 6.00008C0.5 9.22182 3.11159 11.8334 6.33333 11.8334C9.55507 11.8334 12.1667 9.22182 12.1667 6.00008C12.1667 2.77834 9.55507 0.166748 6.33333 0.166748ZM8.26892 8.57804C8.17718 8.6693 8.08098 8.76503 8.00289 8.84336C7.93256 8.91393 7.88293 9.00095 7.85776 9.09528C7.82224 9.22841 7.79355 9.36295 7.74556 9.49208L7.33653 10.5941C7.01287 10.6646 6.67792 10.7044 6.33333 10.7044V10.0604C6.37308 9.76352 6.15363 9.20747 5.80104 8.85489C5.65991 8.71376 5.58065 8.52229 5.58065 8.32259V7.56967C5.58065 7.29588 5.43317 7.0442 5.19348 6.91178C4.85548 6.72478 4.3747 6.46345 4.0454 6.29763C3.77537 6.16167 3.52557 5.98856 3.30094 5.78604L3.28212 5.7691C3.12149 5.6241 2.97886 5.46031 2.85733 5.28126C2.63669 4.95737 2.27728 4.42461 2.04372 4.07837C2.5252 3.00815 3.39291 2.14867 4.47114 1.68177L5.03589 1.96426C5.28616 2.0894 5.58065 1.90757 5.58065 1.62767V1.36188C5.76858 1.33153 5.95981 1.31225 6.15433 1.30495L6.81999 1.97061C6.967 2.11762 6.967 2.35589 6.81999 2.5029L6.70968 2.61298L6.46646 2.8562C6.39308 2.92958 6.39308 3.04884 6.46646 3.12223L6.57678 3.23254C6.65017 3.30593 6.65017 3.42518 6.57678 3.49857L6.38861 3.68674C6.35328 3.722 6.30539 3.7418 6.25548 3.74178H6.04402C5.99509 3.74178 5.94805 3.76083 5.91277 3.79518L5.67944 4.02216C5.65083 4.05001 5.63182 4.08623 5.62514 4.12559C5.61846 4.16495 5.62446 4.20541 5.64227 4.24114L6.00897 4.97478C6.07154 5.09991 5.98051 5.24716 5.84079 5.24716H5.70813C5.66273 5.24716 5.61899 5.23069 5.58488 5.20106L5.3666 5.01147C5.3172 4.96862 5.25751 4.93936 5.19338 4.92658C5.12925 4.91379 5.06289 4.91792 5.00084 4.93856L4.26767 5.18294C4.2117 5.20161 4.16302 5.23741 4.12853 5.28529C4.09404 5.33316 4.07549 5.39067 4.0755 5.44968C4.0755 5.55623 4.13572 5.65337 4.23098 5.70112L4.4916 5.83143C4.71294 5.94222 4.95709 5.99985 5.20454 5.99985C5.45198 5.99985 5.73589 6.64175 5.95722 6.75253H7.52729C7.72698 6.75253 7.91821 6.8318 8.05958 6.97293L8.38159 7.29494C8.51611 7.42952 8.59167 7.61202 8.59163 7.8023C8.59159 7.94648 8.56305 8.08924 8.50767 8.22237C8.45229 8.35549 8.37115 8.47636 8.26892 8.57804ZM10.3085 6.42935C10.1723 6.39524 10.0535 6.31174 9.97564 6.19484L9.55272 5.56046C9.49084 5.46778 9.45781 5.35884 9.45781 5.24739C9.45781 5.13595 9.49084 5.02701 9.55272 4.93432L10.0135 4.24326C10.0681 4.16164 10.1429 4.09531 10.2308 4.05156L10.5362 3.89891C10.8542 4.5321 11.0376 5.24434 11.0376 6.00008C11.0376 6.20401 11.0202 6.40371 10.9948 6.60082L10.3085 6.42935Z" fill="white" /> </svg> <select class="menu--language__list" onchange="window.open(this.options[this.selectedIndex].value, '_self');"> <option value="https://linuxfoundation.org/">English</option> <option value="https://www.linuxfoundation.jp">Japan</option> <option value="https://www.linuxfoundation.org/zh/chinese/">China</option> <option value="https://linuxfoundation.eu">Europe</option> </select> </div> <div class="top__bar-menu text-color--white"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://openprofile.dev/" role="menuitem" target="_blank" rel="noopener">Sign In</a></li> </ul> </div></span> </div> <a href="#search-popup" class="search-popup-link"> <svg width="18" height="18" class="icon icon-search header-search-icon" viewbox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg"> <path d="M12.0409 0.757324C8.07935 0.757324 4.85339 3.98328 4.85339 7.94482C4.85339 9.66589 5.45703 11.2438 6.47058 12.4819L0.743042 18.2095L1.77625 19.2427L7.50378 13.5151C8.74194 14.5287 10.3198 15.1323 12.0409 15.1323C16.0024 15.1323 19.2284 11.9064 19.2284 7.94482C19.2284 3.98328 16.0024 0.757324 12.0409 0.757324ZM12.0409 2.19482C15.2247 2.19482 17.7909 4.76099 17.7909 7.94482C17.7909 11.1287 15.2247 13.6948 12.0409 13.6948C8.85706 13.6948 6.29089 11.1287 6.29089 7.94482C6.29089 4.76099 8.85706 2.19482 12.0409 2.19482Z" fill="white" /> </svg> </a> <div id="search-popup" class="hs-search-field mfp-hide"> <h4> Search </h4> <div class="hs-search-field__bar"> <form action="/hs-search-results"> <input type="text" class="hs-search-field__input" name="term" autocomplete="off" aria-label="Search" placeholder="Search the site..."> <input type="hidden" name="type" value="SITE_PAGE"> <input type="hidden" name="type" value="LANDING_PAGE"> <input type="hidden" name="type" value="BLOG_POST"> <input type="hidden" name="type" value="LISTING_PAGE"> </form> </div> <ul class="hs-search-field__suggestions"></ul> </div> </div> </div> </div> <header id="js-top-header" class="section-wrapper"> <div class="header__row header__main"> <div class="header_branding"> <a href="/?hsLang=en"> <img src="https://www.linuxfoundation.org/hubfs/LF%20Logo%20White.svg"> </a> </div> <div class="header_content flex-row jc--space-between align-items--center pt--sm pb--sm"> <div class="header-left"> <button class="burger-button menu-toggle" onclick="myFunction(this); openSlideMenu();" type="button"> <span></span> </button> </div> <div class="header-right"> <div class="header-button"> <a class="hs-button hs-button--primary mt--none" href="https://www.linuxfoundation.org/about/join?hsLang=en"> Join </a> </div> </div> </div> </div> </header> <nav class="mega-menu__nav-menu bg--white mega__menu" role="navigation"> <div class="mega__menu-content"> <div class="row"> <div id="burger-menu"> <div class="menu-items section-wrapper flex-row jc--space-between pt--md pb--md"> <div class="menu__row-list open-menu--1"> <div class="child-menu dropdown--1" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--1"></label> ABOUT </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about" role="menuitem" target="_self">About the LF</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/members" role="menuitem" target="_self">Corporate Members</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/individual-supporters" role="menuitem" target="_self">Individual Supporters</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/leadership" role="menuitem" target="_self">Leadership</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/diversity-inclusivity" role="menuitem" target="_self">Diversity &amp; Inclusivity</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/careers" role="menuitem" target="_self">Careers</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/brand-guidelines" role="menuitem" target="_self">Brand Guidelines</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/contact" role="menuitem" target="_self">Contact Us</a></li> </ul> </div></span> </div> </div> </div> <div class="menu__row-list open-menu--2"> <div class="child-menu dropdown--1" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--1"></label> PROJECTS </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu" class="active-branch"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects" role="menuitem" target="_self">View All Projects</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/hosting" role="menuitem" target="_self">Host Your Project</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/partnerships" role="menuitem" target="_self">Partner Program</a></li> <li class="hs-menu-item hs-menu-depth-1 active active-branch" role="none"><a href="https://www.linuxfoundation.org/security" role="menuitem" target="_self">Security</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/standards" role="menuitem" target="_self">Standards and Specifications</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/digital-trust" role="menuitem" target="_self">Digital Trust</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/sustainability" role="menuitem" target="_self">Sustainability</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/management" role="menuitem" target="_self">Management &amp; Best Practices</a></li> </ul> </div></span> </div> </div> </div> <div class="menu__row-list open-menu--3"> <div class="child-menu dropdown--1" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--1"></label> RESOURCES </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/blog" role="menuitem" target="_self">Blog</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/resources/publications" role="menuitem" target="_self">Publications</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/resources/open-source-guides" role="menuitem" target="_self">Open Source Guides</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/webinars" role="menuitem" target="_self">Webinars</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/resources/case-studies" role="menuitem" target="_self">Case Studies</a></li> </ul> </div></span> </div> </div> <div class="child-menu dropdown--2" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--2"></label> NEWSROOM </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/press" role="menuitem" target="_self">Press Releases</a></li> </ul> </div></span> </div> </div> </div> <div class="menu__row-list open-menu--4"> <div class="child-menu dropdown--1" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--1"></label> LF RESEARCH </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research" role="menuitem" target="_self">Latest Research</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research/leadership" role="menuitem" target="_self">Leadership &amp; Advisory Board</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research/surveys" role="menuitem" target="_self">Surveys</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research/lfr-forum" role="menuitem" target="_self">Research Forum</a></li> </ul> </div></span> </div> </div> <div class="child-menu dropdown--2" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--2"></label> LF EDUCATION </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://training.linuxfoundation.org" role="menuitem" target="_blank" rel="noopener">Home</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://training.linuxfoundation.org/full-catalog/" role="menuitem" target="_blank" rel="noopener">Course Catalog</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://training.linuxfoundation.org/resources/" role="menuitem" target="_self">Resources</a></li> </ul> </div></span> </div> </div> </div> <div class="menu__row-list open-menu--5"> <div class="child-menu dropdown--1" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--1"></label> EVENTS </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://events.linuxfoundation.org/" role="menuitem" target="_self">Upcoming Events</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://events.linuxfoundation.org/about/sponsor/" role="menuitem" target="_self">Sponsor</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://linuxfoundation.smapply.io/" role="menuitem" target="_self">Submit a Talk</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://events.linuxfoundation.org/about/code-of-conduct/" role="menuitem" target="_self">Code of conduct</a></li> </ul> </div></span> </div> </div> </div> <div class="menu__row-list open-menu--6"> <div class="child-menu dropdown--1" aria-expanded="false"> <p class="row-list-title letter__spacing"> <input type="checkbox" class="menu_arrow menu_arrow-invert" name="menu_arrow" id="menu_arrow"> <label for="menu_arrow dropdown--1"></label> LFX PLATFORM </p> <div class="menu-links"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://lfx.linuxfoundation.org/" role="menuitem" target="_self">LFX Home</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://myprofile.lfx.linuxfoundation.org/" role="menuitem" target="_self">LFX Tools</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://community.lfx.dev/" role="menuitem" target="_self">LFX Community Forum</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://openprofile.dev/" role="menuitem" target="_self">Create an LFX Account</a></li> </ul> </div></span> </div> </div> </div> </div> <div class="mega__menu-footer"> <div class="footer_content section-wrapper flex-row jc--space-between align-items--center pt--xs pb--xs"> <div class="footer-left col6 flex-row align-items--center"> <div class="header-button__wrapper mobile-only"> <div class="header-button"> <a class="hs-button hs-button--primary mt--none" href="https://www.linuxfoundation.org/about/join?hsLang=en"> Join </a> </div> </div> <p class="footer-social-title letter__spacing">Follow Us</p> <div class="footer-social-icons"> <a href="https://twitter.com/linuxfoundation" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 512 512" aria-hidden="true"><g id="Twitter1_layer"><path d="M459.37 151.716c.325 4.548.325 9.097.325 13.645 0 138.72-105.583 298.558-298.558 298.558-59.452 0-114.68-17.219-161.137-47.106 8.447.974 16.568 1.299 25.34 1.299 49.055 0 94.213-16.568 130.274-44.832-46.132-.975-84.792-31.188-98.112-72.772 6.498.974 12.995 1.624 19.818 1.624 9.421 0 18.843-1.3 27.614-3.573-48.081-9.747-84.143-51.98-84.143-102.985v-1.299c13.969 7.797 30.214 12.67 47.431 13.319-28.264-18.843-46.781-51.005-46.781-87.391 0-19.492 5.197-37.36 14.294-52.954 51.655 63.675 129.3 105.258 216.365 109.807-1.624-7.797-2.599-15.918-2.599-24.04 0-57.828 46.782-104.934 104.934-104.934 30.213 0 57.502 12.67 76.67 33.137 23.715-4.548 46.456-13.32 66.599-25.34-7.798 24.366-24.366 44.833-46.132 57.827 21.117-2.273 41.584-8.122 60.426-16.243-14.292 20.791-32.161 39.308-52.628 54.253z" /></g></svg></span> </a> <a href="https://www.facebook.com/TheLinuxFoundation" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 320 512" aria-hidden="true"><g id="Facebook F2_layer"><path d="M279.14 288l14.22-92.66h-88.91v-60.13c0-25.35 12.42-50.06 52.24-50.06h40.42V6.26S260.43 0 225.36 0c-73.22 0-121.08 44.38-121.08 124.72v70.62H22.89V288h81.39v224h100.17V288z" /></g></svg></span> </a> <a href="https://www.youtube.com/user/TheLinuxFoundation" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 576 512" aria-hidden="true"><g id="YouTube3_layer"><path d="M549.655 124.083c-6.281-23.65-24.787-42.276-48.284-48.597C458.781 64 288 64 288 64S117.22 64 74.629 75.486c-23.497 6.322-42.003 24.947-48.284 48.597-11.412 42.867-11.412 132.305-11.412 132.305s0 89.438 11.412 132.305c6.281 23.65 24.787 41.5 48.284 47.821C117.22 448 288 448 288 448s170.78 0 213.371-11.486c23.497-6.321 42.003-24.171 48.284-47.821 11.412-42.867 11.412-132.305 11.412-132.305s0-89.438-11.412-132.305zm-317.51 213.508V175.185l142.739 81.205-142.739 81.201z" /></g></svg></span> </a> <a href="https://www.linkedin.com/company/208777" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512" aria-hidden="true"><g id="LinkedIn In4_layer"><path d="M100.28 448H7.4V148.9h92.88zM53.79 108.1C24.09 108.1 0 83.5 0 53.8a53.79 53.79 0 0 1 107.58 0c0 29.7-24.1 54.3-53.79 54.3zM447.9 448h-92.68V302.4c0-34.7-.7-79.2-48.29-79.2-48.29 0-55.69 37.7-55.69 76.7V448h-92.78V148.9h89.08v40.8h1.3c12.4-23.5 42.69-48.3 87.88-48.3 94 0 111.28 61.9 111.28 142.3V448z" /></g></svg></span> </a> <a href="https://github.com/LF-Engineering" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 496 512" aria-hidden="true"><g id="GitHub5_layer"><path d="M165.9 397.4c0 2-2.3 3.6-5.2 3.6-3.3.3-5.6-1.3-5.6-3.6 0-2 2.3-3.6 5.2-3.6 3-.3 5.6 1.3 5.6 3.6zm-31.1-4.5c-.7 2 1.3 4.3 4.3 4.9 2.6 1 5.6 0 6.2-2s-1.3-4.3-4.3-5.2c-2.6-.7-5.5.3-6.2 2.3zm44.2-1.7c-2.9.7-4.9 2.6-4.6 4.9.3 2 2.9 3.3 5.9 2.6 2.9-.7 4.9-2.6 4.6-4.6-.3-1.9-3-3.2-5.9-2.9zM244.8 8C106.1 8 0 113.3 0 252c0 110.9 69.8 205.8 169.5 239.2 12.8 2.3 17.3-5.6 17.3-12.1 0-6.2-.3-40.4-.3-61.4 0 0-70 15-84.7-29.8 0 0-11.4-29.1-27.8-36.6 0 0-22.9-15.7 1.6-15.4 0 0 24.9 2 38.6 25.8 21.9 38.6 58.6 27.5 72.9 20.9 2.3-16 8.8-27.1 16-33.7-55.9-6.2-112.3-14.3-112.3-110.5 0-27.5 7.6-41.3 23.6-58.9-2.6-6.5-11.1-33.3 2.6-67.9 20.9-6.5 69 27 69 27 20-5.6 41.5-8.5 62.8-8.5s42.8 2.9 62.8 8.5c0 0 48.1-33.6 69-27 13.7 34.7 5.2 61.4 2.6 67.9 16 17.7 25.8 31.5 25.8 58.9 0 96.5-58.9 104.2-114.8 110.5 9.2 7.9 17 22.9 17 46.4 0 33.7-.3 75.4-.3 83.6 0 6.5 4.6 14.4 17.3 12.1C428.2 457.8 496 362.9 496 252 496 113.3 383.5 8 244.8 8zM97.2 352.9c-1.3 1-1 3.3.7 5.2 1.6 1.6 3.9 2.3 5.2 1 1.3-1 1-3.3-.7-5.2-1.6-1.6-3.9-2.3-5.2-1zm-10.8-8.1c-.7 1.3.3 2.9 2.3 3.9 1.6 1 3.6.7 4.3-.7.7-1.3-.3-2.9-2.3-3.9-2-.6-3.6-.3-4.3.7zm32.4 35.6c-1.6 1.3-1 4.3 1.3 6.2 2.3 2.3 5.2 2.6 6.5 1 1.3-1.3.7-4.3-1.3-6.2-2.2-2.3-5.2-2.6-6.5-1zm-11.4-14.7c-1.6 1-1.6 3.6 0 5.9 1.6 2.3 4.3 3.3 5.6 2.3 1.6-1.3 1.6-3.9 0-6.2-1.4-2.3-4-3.3-5.6-2z" /></g></svg></span> </a> </div> </div> <div class="footer-right col6 align-items--center"> <span id="hs_cos_wrapper_module_16560108726164_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16560108726164_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://openprofile.dev/" role="menuitem" target="_self">My Account</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://openprofile.dev/" role="menuitem" target="_self">Log In</a></li> </ul> </div></span> <div class="menu--language mobile-only"> <svg class="icon--globe" width="18" height="18" viewbox="0 0 13 12" fill="none" xmlns="http://www.w3.org/2000/svg"> <path d="M6.33333 0.166748C3.11159 0.166748 0.5 2.77834 0.5 6.00008C0.5 9.22182 3.11159 11.8334 6.33333 11.8334C9.55507 11.8334 12.1667 9.22182 12.1667 6.00008C12.1667 2.77834 9.55507 0.166748 6.33333 0.166748ZM8.26892 8.57804C8.17718 8.6693 8.08098 8.76503 8.00289 8.84336C7.93256 8.91393 7.88293 9.00095 7.85776 9.09528C7.82224 9.22841 7.79355 9.36295 7.74556 9.49208L7.33653 10.5941C7.01287 10.6646 6.67792 10.7044 6.33333 10.7044V10.0604C6.37308 9.76352 6.15363 9.20747 5.80104 8.85489C5.65991 8.71376 5.58065 8.52229 5.58065 8.32259V7.56967C5.58065 7.29588 5.43317 7.0442 5.19348 6.91178C4.85548 6.72478 4.3747 6.46345 4.0454 6.29763C3.77537 6.16167 3.52557 5.98856 3.30094 5.78604L3.28212 5.7691C3.12149 5.6241 2.97886 5.46031 2.85733 5.28126C2.63669 4.95737 2.27728 4.42461 2.04372 4.07837C2.5252 3.00815 3.39291 2.14867 4.47114 1.68177L5.03589 1.96426C5.28616 2.0894 5.58065 1.90757 5.58065 1.62767V1.36188C5.76858 1.33153 5.95981 1.31225 6.15433 1.30495L6.81999 1.97061C6.967 2.11762 6.967 2.35589 6.81999 2.5029L6.70968 2.61298L6.46646 2.8562C6.39308 2.92958 6.39308 3.04884 6.46646 3.12223L6.57678 3.23254C6.65017 3.30593 6.65017 3.42518 6.57678 3.49857L6.38861 3.68674C6.35328 3.722 6.30539 3.7418 6.25548 3.74178H6.04402C5.99509 3.74178 5.94805 3.76083 5.91277 3.79518L5.67944 4.02216C5.65083 4.05001 5.63182 4.08623 5.62514 4.12559C5.61846 4.16495 5.62446 4.20541 5.64227 4.24114L6.00897 4.97478C6.07154 5.09991 5.98051 5.24716 5.84079 5.24716H5.70813C5.66273 5.24716 5.61899 5.23069 5.58488 5.20106L5.3666 5.01147C5.3172 4.96862 5.25751 4.93936 5.19338 4.92658C5.12925 4.91379 5.06289 4.91792 5.00084 4.93856L4.26767 5.18294C4.2117 5.20161 4.16302 5.23741 4.12853 5.28529C4.09404 5.33316 4.07549 5.39067 4.0755 5.44968C4.0755 5.55623 4.13572 5.65337 4.23098 5.70112L4.4916 5.83143C4.71294 5.94222 4.95709 5.99985 5.20454 5.99985C5.45198 5.99985 5.73589 6.64175 5.95722 6.75253H7.52729C7.72698 6.75253 7.91821 6.8318 8.05958 6.97293L8.38159 7.29494C8.51611 7.42952 8.59167 7.61202 8.59163 7.8023C8.59159 7.94648 8.56305 8.08924 8.50767 8.22237C8.45229 8.35549 8.37115 8.47636 8.26892 8.57804ZM10.3085 6.42935C10.1723 6.39524 10.0535 6.31174 9.97564 6.19484L9.55272 5.56046C9.49084 5.46778 9.45781 5.35884 9.45781 5.24739C9.45781 5.13595 9.49084 5.02701 9.55272 4.93432L10.0135 4.24326C10.0681 4.16164 10.1429 4.09531 10.2308 4.05156L10.5362 3.89891C10.8542 4.5321 11.0376 5.24434 11.0376 6.00008C11.0376 6.20401 11.0202 6.40371 10.9948 6.60082L10.3085 6.42935Z" fill="black" /> </svg> <a href="https://linuxfoundation.org/" target="_blank">English</a>&nbsp;|&nbsp; <a href="https://www.linuxfoundation.jp" target="_blank">Japan</a>&nbsp;|&nbsp; <a href="https://www.linuxfoundation.org/zh/chinese/?hsLang=en" target="_blank">China</a>&nbsp;|&nbsp; <a href="https://linuxfoundation.eu?hsLang=en" target="_blank">Europe</a> </div> </div> </div> </div> </div> </div> </div> </nav> </section></div> <main id="main"> <main id="main-content" class="body-container-wrapper"> <div class="container-fluid main"> <div class="row-fluid-wrapper"> <div class="row-fluid"> <div class="span12 widget-span widget-type-cell " style="" data-widget-type="cell" data-x="0" data-w="12"> <div class="row-fluid-wrapper row-depth-1 row-number-1 dnd-section"> <div class="row-fluid "> <div class="span12 widget-span widget-type-cell dnd-column" style="" data-widget-type="cell" data-x="0" data-w="12"> <div class="row-fluid-wrapper row-depth-1 row-number-2 dnd-row"> <div class="row-fluid "> <div class="span12 widget-span widget-type-custom_widget dnd-module" style="" data-widget-type="custom_widget" data-x="0" data-w="12"> <div id="hs_cos_wrapper_widget_1662314064030" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style="" data-hs-cos-general-type="widget" data-hs-cos-type="module"> <section id="" class="section--widget_1662314064030 section--one-col section--dark bg--gradient bg align--left" style=" "> <div class="one-col section-wrapper pt--md pb--md" style=""> <div class="one-col__wrapper"> <div class="one-col__container flex-row jc--space-between align-items--center"> <div class="col12 one-col__inner align--center"> <h6>Security</h6> <h1 class="one-col__title">How to report vulnerabilities to LF projects and foundations</h1> </div> <div class=" one-col__inner align--center"> </div> </div> </div> </div> </section></div> </div><!--end widget-span --> </div><!--end row--> </div><!--end row-wrapper --> <div class="row-fluid-wrapper row-depth-1 row-number-3 dnd-row"> <div class="row-fluid "> <div class="span12 widget-span widget-type-custom_widget dnd-module" style="" data-widget-type="custom_widget" data-x="0" data-w="12"> <div id="hs_cos_wrapper_widget_1662314056838" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style="" data-hs-cos-general-type="widget" data-hs-cos-type="module"> <section id="" class="section--widget_1662314056838 section--one-col section--light bg--white bg align--left" style=" "> <div class="one-col section-wrapper pt--md pb--md" style=""> <div class="one-col__wrapper"> <div class="one-col__container flex-row jc--space-between"> <div class="col12 one-col__inner"> <div class="one-col__supporting-content"> <p>We at the Linux Foundation (LF), along with our many contributors, work to develop secure software in our foundations and projects. We also work to secure the infrastructure and processes we use. Sadly, mistakes can happen. So, if you discover a security vulnerability in something we do, please tell us!</p> <p>If you find a security vulnerability in the software developed by an LF foundation or project, or in how we develop the software, please report the vulnerability <strong><em>directly</em></strong> to that foundation or project, using their vulnerability reporting process and policy. Examples of such processes/policies are (alphabetically) those of <a href="https://community.finos.org/docs/governance/software-projects/cve-responsible-disclosure/">FINOS</a>, <a href="https://kubernetes.io/docs/reference/issues-security/security/">Kubernetes</a>, <a href="https://www.kernel.org/doc/html/latest/process/security-bugs.html">the Linux kernel</a>, <a href="https://wiki.yoctoproject.org/wiki/Security#Yocto_Security_Team">Yocto</a>, and <a href="https://zephyrproject.org/security/">Zephyr</a>. Feel free to browse <a href="https://www.linuxfoundation.org/projects?hsLang=en">our list of foundations/projects</a>.</p> <p>If you find a security vulnerability in either the LF infrastructure (as a whole) or the main LF website, please privately report it to <a href="mailto:security@linuxfoundation.org">security@linuxfoundation.org</a>. <strong><em>Do not send</em></strong> vulnerability reports there for <strong><em>any</em></strong> other situation (such as for the Linux kernel or any other project); such reports will typically be ignored. Instead, send the project vulnerability report directly to the relevant foundation/project.</p> <h2>Guidance</h2> <p>The vulnerability reporting process is often described in the file SECURITY.md of its source repository, among other places. This process will typically involve one of:</p> <ol> <li>Sending an email to security@DOMAIN where DOMAIN is the domain of the project/foundation. For example, Linux kernel security vulnerabilities should be reported to <a href="mailto:security@kernel.org" rel="noopener">security@kernel.org</a> as described in the <a href="https://www.kernel.org/doc/html/latest/process/security-bugs.html">Linux kernel security bugs page</a>. In some cases, different email address(es) other than “security” will be recommended.</li> <li>Using GitHub’s ability to <a href="https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability#privately-reporting-a-security-vulnerability">privately report a security vulnerability</a>, if the project is hosted on GitHub. In cases where private reporting has been enabled, please use it.</li> </ol> <p>If a specific LF project doesn’t state how to report a vulnerability, report the vulnerability to the <a href="https://www.linuxfoundation.org/projects?hsLang=en">foundation</a> that runs the project using its process. Also, if an LF project or foundation doesn’t make it clear how to report vulnerabilities, please ask them to clarify their process so that you can then report the vulnerability. If a project doesn’t respond in any way to a report, after some time retransmit it several times in case it was accidentally dropped. Please give them time to fix it before making the vulnerability public (many ask for up to 90 days from the initial report). If the project/foundation is marked as no longer being maintained (e.g., it is “archived” or “abandoned”), then reporters may directly report the vulnerability to the public, but they must also clearly note that the project is already marked as being no longer maintained.</p> <p>Vulnerability finders (aka security researchers) who discover security vulnerabilities, and aren’t familiar with how to report vulnerabilities to open source software (OSS) projects, should consult the OpenSSF “<a href="https://github.com/ossf/oss-vulnerability-guide/blob/main/finder-guide.md#readme">Guidance for Security Researchers to Coordinate Vulnerability Disclosures with Open Source Software Projects</a>”. You must provide specific information about the vulnerability so it can be rapidly identified, verified as a true (exploitable) vulnerability, and corrected. In particular, a data dump from a fuzzer or a static analysis tool is normally insufficient and is not considered a valid vulnerability report. If the project/foundation has a bug bounty program, payment (if applicable) occurs as defined by its bug bounty program. Otherwise, please do not expect that you’ll be paid for a vulnerability report, as we have limited resources. Please make it clear in your report whether or not you would like public credit when the vulnerability is publicly announced (we typically assume you want public credit).<br><br>If the vulnerability isn’t already publicly and widely known, our projects typically ask that you privately report vulnerabilities with time to fix them (often up to 90 days). If such vulnerabilities are publicly reported, attackers may exploit the software while maintainers are still working on a fix. So, unless otherwise required by law, do not publicly report the details of an otherwise unknown vulnerability or share that information with anyone likely to exploit the vulnerability, until either the project has time to fix the vulnerability or the project says it is fine to make it public.<br><br>If you have specific recommendations on how to improve a particular foundation / project, beyond fixing specific vulnerabilities, please work with the foundation / project to help them improve their processes and results.</p> <h2>For LF foundations and projects</h2> <p>If you <em>lead</em> an LF foundation, or <em>maintain</em> an LF project, we ask that you take steps to (1) make it <em>easy</em> for vulnerability finders (e.g. users or security researchers) to report vulnerabilities, and (2) be ready to receive those reports. The OpenSSF “<a href="https://github.com/ossf/oss-vulnerability-guide/blob/main/maintainer-guide.md#readme">Guide to implementing a coordinated vulnerability disclosure process for open source projects</a>” can help you do that. As noted above, vulnerability reports are typically sent to security@YOUR_DOMAIN and/or a private reporting mechanism; this should be noted in a SECURITY.md file and README file where appropriate. As noted above, please give public credit to the finder when the vulnerability is publicly announced (unless the finder has requested that they not receive public credit).</p> <p>We also encourage you to make vulnerabilities less likely. For example, we encourage you to <a href="https://openssf.org/training/courses/?hsLang=en">learn how to develop secure software</a>, as well as use practices to counter vulnerabilities (e.g., see the <a href="https://best.openssf.org/Concise-Guide-for-Developing-More-Secure-Software">Concise Guide for Developing More Secure Software</a>, <a href="https://best.openssf.org/Concise-Guide-for-Evaluating-Open-Source-Software">Concise Guide for Evaluating Open Source Software</a>, <a href="https://securityscorecards.dev/">the OpenSSF Security Scorecard</a>, and the <a href="https://bestpractices.coreinfrastructure.org/">OpenSSF Best Practices badge</a>). Each of the LF foundations and projects is expected to try to develop software that is adequately secure for its purpose, apply good practices to counter attacks (including supply chain attacks), and continuously improve.</p> <p>The Linux Foundation is also working to make open source software (OSS) even more secure in general. The <a href="https://openssf.org/?hsLang=en">Open Source Security Foundation (OpenSSF)</a> is a broad initiative to secure the OSS that we all depend on. Please check out the <a href="https://openssf.org/?hsLang=en">OpenSSF</a> if you’re interested in learning more.</p> <h2>Acceptable approaches</h2> <p>There are laws and regulations that may impact security research. You should become familiar with them and consult legal counsel if you have any questions. The Linux Foundation cannot provide you with legal advice and it is your responsibility to comply with applicable laws. We welcome your vulnerability report contributions; they are valuable contributions to our communities and the ecosystems dependent on the projects. The Linux Foundation itself will not pursue legal action against anyone for performing vulnerability analysis on our projects or for disclosing vulnerabilities to our projects (e.g. using the project’s defined process).<br><br>If you have concerns or are uncertain whether your approach to security research is acceptable with a specific foundation or project, please contact the foundation / project community first.</p> </div> </div> </div> </div> </div> </section></div> </div><!--end widget-span --> </div><!--end row--> </div><!--end row-wrapper --> </div><!--end widget-span --> </div><!--end row--> </div><!--end row-wrapper --> </div><!--end widget-span --> </div> </div> </div> </main> </main> <div id="hs_cos_wrapper_module_16613593312364" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_module" style="" data-hs-cos-general-type="widget" data-hs-cos-type="module"> <section id="sticky-form" class="section--module_16613593312364 section--footer_form "> <div class="form__container hs-form bg--secondary pb--md pt--md"> <div class="section-wrapper"> <div class="footer_form_title"><h3>Stay Connected with the Linux Foundation</h3></div> <div class="footer__form align-items--center"> <span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_form" style="" data-hs-cos-general-type="widget" data-hs-cos-type="form"><h3 id="hs_cos_wrapper_form_8432498_title" class="hs_cos_wrapper form-title" data-hs-cos-general-type="widget_field" data-hs-cos-type="text"></h3> <div id="hs_form_target_form_8432498"></div> </span> </div> </div> </div> </section> <footer class="section--module_16613593312364 section--footer pt--xs"> <div class="footer section-wrapper"> <div class="footer__wrapper"> <div class="footer__container flex-row jc--space-between"> <div class="footer__left pt--xs col4"> <div class="footer__logo"> <a href="https://linuxfoundation.org"> <img src="https://www.linuxfoundation.org/hubfs/LF%20Logo%20White.svg" alt="LF Logo White" height="50" style="height:50px;"> </a> </div> <p class="footer__title">ABOUT THE LINUX FOUNDATION</p> <p class="footer__content">The Linux Foundation provides a neutral, trusted hub for developers to code, manage, and scale open technology projects.</p> <div class="footer__info-menu"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about" role="menuitem" target="_self">About the LF</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/leadership" role="menuitem" target="_self">Leadership</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/careers" role="menuitem" target="_self">Careers</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/members" role="menuitem" target="_self">Corporate Members</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/diversity-inclusivity" role="menuitem" target="_self">Diversity &amp; Inclusivity</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/brand-guidelines" role="menuitem" target="_self">Brand Guidelines</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/about/contact" role="menuitem" target="_self">Contact Us</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://linuxfoundation.store/" role="menuitem" target="_blank" rel="noopener">Store</a></li> </ul> </div></span></div> <div class="footer__social-links"> <a href="https://twitter.com/linuxfoundation" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 512 512" aria-hidden="true"><g id="Twitter1_layer"><path d="M459.37 151.716c.325 4.548.325 9.097.325 13.645 0 138.72-105.583 298.558-298.558 298.558-59.452 0-114.68-17.219-161.137-47.106 8.447.974 16.568 1.299 25.34 1.299 49.055 0 94.213-16.568 130.274-44.832-46.132-.975-84.792-31.188-98.112-72.772 6.498.974 12.995 1.624 19.818 1.624 9.421 0 18.843-1.3 27.614-3.573-48.081-9.747-84.143-51.98-84.143-102.985v-1.299c13.969 7.797 30.214 12.67 47.431 13.319-28.264-18.843-46.781-51.005-46.781-87.391 0-19.492 5.197-37.36 14.294-52.954 51.655 63.675 129.3 105.258 216.365 109.807-1.624-7.797-2.599-15.918-2.599-24.04 0-57.828 46.782-104.934 104.934-104.934 30.213 0 57.502 12.67 76.67 33.137 23.715-4.548 46.456-13.32 66.599-25.34-7.798 24.366-24.366 44.833-46.132 57.827 21.117-2.273 41.584-8.122 60.426-16.243-14.292 20.791-32.161 39.308-52.628 54.253z" /></g></svg></span></a> <a href="https://www.facebook.com/TheLinuxFoundation" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 320 512" aria-hidden="true"><g id="Facebook F2_layer"><path d="M279.14 288l14.22-92.66h-88.91v-60.13c0-25.35 12.42-50.06 52.24-50.06h40.42V6.26S260.43 0 225.36 0c-73.22 0-121.08 44.38-121.08 124.72v70.62H22.89V288h81.39v224h100.17V288z" /></g></svg></span></a> <a href="https://www.youtube.com/user/TheLinuxFoundation" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 576 512" aria-hidden="true"><g id="YouTube3_layer"><path d="M549.655 124.083c-6.281-23.65-24.787-42.276-48.284-48.597C458.781 64 288 64 288 64S117.22 64 74.629 75.486c-23.497 6.322-42.003 24.947-48.284 48.597-11.412 42.867-11.412 132.305-11.412 132.305s0 89.438 11.412 132.305c6.281 23.65 24.787 41.5 48.284 47.821C117.22 448 288 448 288 448s170.78 0 213.371-11.486c23.497-6.321 42.003-24.171 48.284-47.821 11.412-42.867 11.412-132.305 11.412-132.305s0-89.438-11.412-132.305zm-317.51 213.508V175.185l142.739 81.205-142.739 81.201z" /></g></svg></span></a> <a href="https://www.linkedin.com/company/208777" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512" aria-hidden="true"><g id="LinkedIn In4_layer"><path d="M100.28 448H7.4V148.9h92.88zM53.79 108.1C24.09 108.1 0 83.5 0 53.8a53.79 53.79 0 0 1 107.58 0c0 29.7-24.1 54.3-53.79 54.3zM447.9 448h-92.68V302.4c0-34.7-.7-79.2-48.29-79.2-48.29 0-55.69 37.7-55.69 76.7V448h-92.78V148.9h89.08v40.8h1.3c12.4-23.5 42.69-48.3 87.88-48.3 94 0 111.28 61.9 111.28 142.3V448z" /></g></svg></span></a> <a href="https://github.com/LF-Engineering" target="_blank" rel="noopener"> <span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_icon" style="" data-hs-cos-general-type="widget" data-hs-cos-type="icon"><svg version="1.0" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 496 512" aria-hidden="true"><g id="GitHub5_layer"><path d="M165.9 397.4c0 2-2.3 3.6-5.2 3.6-3.3.3-5.6-1.3-5.6-3.6 0-2 2.3-3.6 5.2-3.6 3-.3 5.6 1.3 5.6 3.6zm-31.1-4.5c-.7 2 1.3 4.3 4.3 4.9 2.6 1 5.6 0 6.2-2s-1.3-4.3-4.3-5.2c-2.6-.7-5.5.3-6.2 2.3zm44.2-1.7c-2.9.7-4.9 2.6-4.6 4.9.3 2 2.9 3.3 5.9 2.6 2.9-.7 4.9-2.6 4.6-4.6-.3-1.9-3-3.2-5.9-2.9zM244.8 8C106.1 8 0 113.3 0 252c0 110.9 69.8 205.8 169.5 239.2 12.8 2.3 17.3-5.6 17.3-12.1 0-6.2-.3-40.4-.3-61.4 0 0-70 15-84.7-29.8 0 0-11.4-29.1-27.8-36.6 0 0-22.9-15.7 1.6-15.4 0 0 24.9 2 38.6 25.8 21.9 38.6 58.6 27.5 72.9 20.9 2.3-16 8.8-27.1 16-33.7-55.9-6.2-112.3-14.3-112.3-110.5 0-27.5 7.6-41.3 23.6-58.9-2.6-6.5-11.1-33.3 2.6-67.9 20.9-6.5 69 27 69 27 20-5.6 41.5-8.5 62.8-8.5s42.8 2.9 62.8 8.5c0 0 48.1-33.6 69-27 13.7 34.7 5.2 61.4 2.6 67.9 16 17.7 25.8 31.5 25.8 58.9 0 96.5-58.9 104.2-114.8 110.5 9.2 7.9 17 22.9 17 46.4 0 33.7-.3 75.4-.3 83.6 0 6.5 4.6 14.4 17.3 12.1C428.2 457.8 496 362.9 496 252 496 113.3 383.5 8 244.8 8zM97.2 352.9c-1.3 1-1 3.3.7 5.2 1.6 1.6 3.9 2.3 5.2 1 1.3-1 1-3.3-.7-5.2-1.6-1.6-3.9-2.3-5.2-1zm-10.8-8.1c-.7 1.3.3 2.9 2.3 3.9 1.6 1 3.6.7 4.3-.7.7-1.3-.3-2.9-2.3-3.9-2-.6-3.6-.3-4.3.7zm32.4 35.6c-1.6 1.3-1 4.3 1.3 6.2 2.3 2.3 5.2 2.6 6.5 1 1.3-1.3.7-4.3-1.3-6.2-2.2-2.3-5.2-2.6-6.5-1zm-11.4-14.7c-1.6 1-1.6 3.6 0 5.9 1.6 2.3 4.3 3.3 5.6 2.3 1.6-1.3 1.6-3.9 0-6.2-1.4-2.3-4-3.3-5.6-2z" /></g></svg></span></a> </div> </div> <div class="footer__right col8 pt--xs align-items--top"> <div class="footer__right-content"> <div class="footer__right-content-menu menu-items-footer flex-row"> <div class="footer__row-list open-menu--1"> <div class="menu-group col3"> <div class="child-menu_links dropdown--1" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--1"></label> <p class="footer__menu-title letter__spacing">PROJECTS</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu" class="active-branch"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects" role="menuitem" target="_self">View All Projects</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/projects/hosting" role="menuitem" target="_self">Host Your Project</a></li> <li class="hs-menu-item hs-menu-depth-1 active active-branch" role="none"><a href="https://www.linuxfoundation.org/security" role="menuitem" target="_self">Security</a></li> </ul> </div></span></div> </div> </div> <div class="menu-group col3"> <div class="child-menu_links dropdown--2" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--2"></label> <p class="footer__menu-title letter__spacing">NEWSROOM</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/press" role="menuitem" target="_self">Press Releases</a></li> </ul> </div></span></div> </div> </div> <div class="menu-group col3"> <div class="child-menu_links dropdown--3" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--3"></label> <p class="footer__menu-title letter__spacing">LF RESEARCH</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research" role="menuitem" target="_self">Latest Research</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research/sponsorship" role="menuitem" target="_self">Sponsor a Study</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research/leadership" role="menuitem" target="_self">Leadership &amp; Advisory Board</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/research/lfr-forum" role="menuitem" target="_self">Research Forum</a></li> </ul> </div></span></div> </div> </div> <div class="menu-group col3"> <div class="child-menu_links dropdown--4" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--4"></label> <p class="footer__menu-title letter__spacing">LFX PLATFORM</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://lfx.linuxfoundation.org" role="menuitem" target="_blank" rel="noopener">LFX Home</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://myprofile.lfx.linuxfoundation.org/" role="menuitem" target="_blank" rel="noopener">LFX Tools</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://community.lfx.dev/" role="menuitem" target="_blank" rel="noopener">LFX Community Forum</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://openprofile.dev/" role="menuitem" target="_blank" rel="noopener">Create an LFX Account</a></li> </ul> </div></span></div> </div> </div> </div> <div class="footer__row-list open-menu--2"> <div class="menu-group col3"> <div class="child-menu_links dropdown--1" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--1"></label> <p class="footer__menu-title letter__spacing">RESOURCES</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/blog" role="menuitem" target="_self">Blog</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/resources/publications" role="menuitem" target="_self">Publications</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/resources/open-source-guides" role="menuitem" target="_self">Open Source Guides</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/webinars" role="menuitem" target="_self">Webinars</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://www.linuxfoundation.org/resources/case-studies" role="menuitem" target="_self">Case Studies</a></li> </ul> </div></span></div> </div> </div> <div class="menu-group col3"> <div class="child-menu_links dropdown--2" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--2"></label> <p class="footer__menu-title letter__spacing">EVENTS</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://events.linuxfoundation.org/about/calendar/" role="menuitem" target="_blank" rel="noopener">Upcoming Events</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://events.linuxfoundation.org/about/sponsor/" role="menuitem" target="_blank" rel="noopener">Sponsor an Event</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://linuxfoundation.smapply.io/" role="menuitem" target="_blank" rel="noopener">Submit a Talk</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://events.linuxfoundation.org/about/code-of-conduct/" role="menuitem" target="_blank" rel="noopener">Code of Conduct</a></li> </ul> </div></span></div> </div> </div> <div class="menu-group col3"> <div class="child-menu_links dropdown--3" aria-expanded="false"> <input class="footer_menu_arrow footer_menu_arrow-invert" type="checkbox" name="footer_menu_arrow" id="footer_menu_arrow"> <label for="footer_menu_arrow dropdown--3"></label> <p class="footer__menu-title letter__spacing">LF EDUCATION</p> <div class="menu-row"><span id="hs_cos_wrapper_module_16613593312364_" class="hs_cos_wrapper hs_cos_wrapper_widget hs_cos_wrapper_type_simple_menu" style="" data-hs-cos-general-type="widget" data-hs-cos-type="simple_menu"><div id="hs_menu_wrapper_module_16613593312364_" class="hs-menu-wrapper active-branch flyouts hs-menu-flow-horizontal" role="navigation" data-sitemap-name="" data-menu-id="" aria-label="Navigation Menu"> <ul role="menu"> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://training.linuxfoundation.org/" role="menuitem" target="_blank" rel="noopener">Home</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://training.linuxfoundation.org/full-catalog/" role="menuitem" target="_self">Course Catalog</a></li> <li class="hs-menu-item hs-menu-depth-1" role="none"><a href="https://training.linuxfoundation.org/resources/" role="menuitem" target="_self">Resources</a></li> </ul> </div></span></div> </div> </div> </div> </div> </div> <div class="footer__info"> <p class="content_info"><span style="font-size: 14px; color: #ffffff;">Copyright © 2024 The Linux Foundation®. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our <a href="/legal/trademark-usage?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Trademark Usage</a> page. Linux is a registered trademark of Linus Torvalds. <a href="/legal/terms/?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Terms of Use</a> | <a href="/legal/privacy-policy/?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Privacy Policy</a> | <a href="/legal/bylaws/?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Bylaws</a> | <a href="/legal/antitrust-policy/?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Antitrust Policy</a> | <a href="/legal/good-standing-policy/?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Good Standing Policy</a> | <a href="/legal/generative-ai?hsLang=en" rel="noopener" style="font-size: 14px; color: #ffffff;">Generative AI Policy</a></span></p> </div> </div> </div> </div> </div> </footer></div> <!-- HubSpot performance collection script --> <script defer src="/hs/hsstatic/content-cwv-embed/static-1.1293/embed.js"></script> <script src="https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js"></script> <script> var hsVars = hsVars || {}; hsVars['language'] = 'en'; </script> <script src="/hs/hsstatic/cos-i18n/static-1.53/bundles/project.js"></script> <script src="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/template_assets/80245626652/1669227112886/2022_-_BZ_Linux_Foundation_Theme/assets/js/magnific-popup.min.js"></script> <script src="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/module_assets/76935915621/1668017286064/module_76935915621_Main_Mega_Header.min.js"></script> <script> function myFunction(x) { x.classList.toggle("change"); } function openSlideMenu() { document.getElementById('burger-menu').classList.toggle("open"); } function closeSlideMenu() { document.getElementById('burger-menu').style.width = '0px'; } </script> <script src="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/template_assets/77282240621/1669227119072/2022_-_BZ_Linux_Foundation_Theme/assets/js/main.min.js"></script> <script src="https://www.linuxfoundation.org/hs-fs/hub/8112310/hub_generated/module_assets/77362524751/1712755318121/module_77362524751_Main_Mega_Footer.min.js"></script> <!--[if lte IE 8]> <script charset="utf-8" src="https://js.hsforms.net/forms/v2-legacy.js"></script> <![endif]--> <script data-hs-allowed="true" src="/_hcms/forms/v2.js"></script> <script data-hs-allowed="true"> var options = { portalId: '8112310', formId: 'e5c83800-1206-402c-9050-decfe094cca8', formInstanceId: '1205', pageId: '132337232805', region: 'na1', pageName: "Security | Linux Foundation", inlineMessage: "Thanks for submitting the form. You have been added to the subscriber list.&nbsp;", rawInlineMessage: "Thanks for submitting the form. You have been added to the subscriber list.&nbsp;", hsFormKey: "2df372eedf068d0811381cde6d17f4b9", css: '', target: '#hs_form_target_form_8432498', contentType: "standard-page", formsBaseUrl: '/_hcms/forms/', formData: { cssClass: 'hs-form stacked hs-custom-form' } }; options.getExtraMetaDataBeforeSubmit = function() { var metadata = {}; if (hbspt.targetedContentMetadata) { var count = hbspt.targetedContentMetadata.length; var targetedContentData = []; for (var i = 0; i < count; i++) { var tc = hbspt.targetedContentMetadata[i]; if ( tc.length !== 3) { continue; } targetedContentData.push({ definitionId: tc[0], criterionId: tc[1], smartTypeId: tc[2] }); } metadata["targetedContentMetadata"] = JSON.stringify(targetedContentData); } return metadata; }; hbspt.forms.create(options); </script> <!-- Start of HubSpot Analytics Code --> <script type="text/javascript"> var _hsq = _hsq || []; _hsq.push(["setContentType", "standard-page"]); _hsq.push(["setCanonicalUrl", "https:\/\/www.linuxfoundation.org\/security"]); _hsq.push(["setPageId", "132337232805"]); _hsq.push(["setContentMetadata", { "contentPageId": 132337232805, "legacyPageId": "132337232805", "contentFolderId": null, "contentGroupId": null, "abTestId": null, "languageVariantId": 132337232805, "languageCode": "en", }]); </script> <script type="text/javascript" id="hs-script-loader" async defer src="/hs/scriptloader/8112310.js?businessUnitId=0"></script> <!-- End of HubSpot Analytics Code --> <script type="text/javascript"> var hsVars = { render_id: "9be421db-64e2-454d-9d96-e7835cae0cf9", ticks: 1732371044127, page_id: 132337232805, content_group_id: 0, portal_id: 8112310, app_hs_base_url: "https://app.hubspot.com", cp_hs_base_url: "https://cp.hubspot.com", language: "en", analytics_page_type: "standard-page", scp_content_type: "", analytics_page_id: "132337232805", category_id: 1, folder_id: 0, is_hubspot_user: false } </script> <script defer src="/hs/hsstatic/HubspotToolsMenu/static-1.354/js/index.js"></script> <!-- Google Tag Manager (noscript) --> <noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-WWBXMJK" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript> <!-- End Google Tag Manager (noscript) --> </body></html>

Pages: 1 2 3 4 5 6 7 8 9 10